You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CloudFormation部署时ACM证书DNS验证持续等待问题排查

问题:ACM证书DNS验证持续处于「validation waiting」状态

问题背景

部署包含Elastic Beanstalk实例、Route53记录及ACM证书的AWS CloudFormation栈后,所有资源创建正常,但ACM证书一直处于「validation waiting」状态,无任何错误提示。Route53记录配置正确,可正常访问Beanstalk页面,但无法通过证书访问。

关联CloudFormation模板

AWSTemplateFormatVersion: "2010-09-09"
Description: Project beanstalk

Parameters:
  ApplicationName:
    Description: Name of your application
    Type: String
    Default: hello
    MinLength: 1
    MaxLength: 255
    AllowedPattern: "^[a-zA-Z][-a-zA-Z0-9]*$"

  EnvironmentName:
    Description: Environment name, either dev or rec or main
    Type: String
    Default: dev
    AllowedValues:
      - dev
      - rec
      - main
    ConstraintDescription: Specify either dev or rec or main

Resources:
  Application:
    Type: AWS::ElasticBeanstalk::Application
    Properties:
      ApplicationName: !Ref ApplicationName

  Environment:
    Type: AWS::ElasticBeanstalk::Environment
    Properties:
      ApplicationName: !Ref Application
      EnvironmentName: !Sub "${ApplicationName}-${EnvironmentName}"
      TemplateName: !Ref ConfigurationTemplate # I disable this part to limit code lines
    DependsOn:
      - ConfigurationTemplate

  Route53APIRecordSet:
    Type: "AWS::Route53::RecordSet"
    Properties:
      Name: !Sub "${ApplicationName}-${EnvironmentName}.api.hello.com"
      Type: "A"
      HostedZoneId: !Ref HostedZoneIdFromMyDNS # This var is hard code in my template
      AliasTarget:
        DNSName: !GetAtt Environment.EndpointURL
        HostedZoneId: !Ref HostedZoneIdFromMyBeanstalk # ELB Zone ID for my region (it's also hardcoded)

  APIACMCertificate:
    Type: "AWS::CertificateManager::Certificate"
    Properties:
      DomainName: hello.com
      ValidationMethod: DNS
      DomainValidationOptions:
        - DomainName: !Sub "${ApplicationName}-${EnvironmentName}.api.hello.com"
          HostedZoneId: !Ref HostedZoneIdFromMyDNS

补充排查信息(2023年8月8日)

执行nslookup命令得到以下结果:

  • nslookup hello.com:响应为Non-authoritative answer, Server unknown
  • nslookup ${ApplicationName}-${EnvironmentName}.api.hello.com:服务器未知,无“非权威答案”提示

核心原因分析

  1. 证书验证覆盖不全:证书的DomainName设为hello.com,ACM会要求验证该主域名的所有权,但你仅在DomainValidationOptions中配置了子域名的验证规则,未包含主域名hello.com,导致CloudFormation未自动创建主域名的DNS验证记录,ACM无法完成主域名的所有权验证,证书一直处于等待状态。
  2. DNS解析异常:从nslookup结果来看,主域名和子域名均存在解析问题,说明域名注册商的NS记录未正确指向Route53托管区的NS服务器,导致ACM验证时无法查询到所需的验证记录。

修复方案

  1. 完善证书验证配置:在DomainValidationOptions中添加主域名hello.com的验证规则,确保CloudFormation为两个域名都生成并配置DNS验证记录:
APIACMCertificate:
  Type: "AWS::CertificateManager::Certificate"
  Properties:
    DomainName: hello.com
    ValidationMethod: DNS
    DomainValidationOptions:
      - DomainName: hello.com
        HostedZoneId: !Ref HostedZoneIdFromMyDNS
      - DomainName: !Sub "${ApplicationName}-${EnvironmentName}.api.hello.com"
        HostedZoneId: !Ref HostedZoneIdFromMyDNS
  1. 修正域名NS记录:登录域名注册商后台,将域名的NS记录更新为Route53托管区提供的4个NS服务器地址,等待DNS全局生效(通常1-24小时)。
  2. 添加资源依赖:为APIACMCertificate添加DependsOn: Route53APIRecordSet,确保证书在Route53记录创建完成后再启动验证流程,避免时序问题。
  3. 验证DNS状态:NS记录生效后,重新执行nslookup确认域名解析正常,同时检查Route53中是否存在ACM生成的CNAME验证记录(格式类似_xxxxxx.hello.com),确认这些记录可被正常解析。

内容的提问来源于stack exchange,提问作者Gati

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 06:47:50